Input validation error in FFmpeg - CVE-2013-0858
Published: December 7, 2013 / Updated: June 8, 2025
Vulnerability identifier: #VU42293
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0858
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
Affected software
FFmpeg
How to mitigate CVE-2013-0858
Install update from vendor's website.
FFmpeg - update to 1.0.4